Privacy should be boring and obvious.
Last updated 8 August 2026. This policy covers two different things: richiest.com, the free fund archive you are reading now, and Richard, the household CFO application at app.richiest.com. Richard connects to real financial accounts, so its section is the one that matters.
The archive (richiest.com)
The fund writeups, guides and calculators collect almost nothing. Calculators run entirely in your browser — the numbers you type are never sent to a server.
- Google Analytics (GA4) page and event data, for measuring which pages are useful.
- Standard web server logs, for reliability and abuse prevention.
The email list that used to run here has been retired. There is no signup form, no list, and no marketing email sent from this domain.
Richard (app.richiest.com)
What Richard collects
- Account information you connect. Richard uses Plaid to link financial institutions. Plaid returns account names, types, balances, transactions, investment holdings and liability details (rates, payments, terms). Richard requests transactions, investments and liabilities.
- What you enter yourself. Property details, private holdings, income streams, goals, debts, gifts, business entities, beneficiaries and household profile answers.
- Account credentials — never. You enter your bank login inside Plaid's own interface. Richard never sees, receives or stores your institution username or password.
- Your email address and a password hash, for signing in.
- Billing details via Stripe. Card numbers go to Stripe, not to Richard. Richard stores only the Stripe customer and subscription identifiers.
Who else processes it
Richard is a small operation and does not pretend otherwise. These are the third parties your data passes through:
- Plaid — the account connection itself.
- Render — hosting for the application and its database.
- Stripe — subscription billing.
- A large language model provider — currently OpenAI. When you ask Richard a question or he writes a briefing, a summary of your financial context (account names, balances, account types, holdings and the findings in question) is sent to that provider to generate the answer. This is worth understanding before you connect anything.
- An email provider (SMTP) — delivering your monthly briefing and account email.
How it is protected
- Plaid access tokens are encrypted at rest with AES-GCM.
- Every request is scoped to your household. Sessions are server-side, referenced by a cookie.
- Traffic is HTTPS end to end.
Richard has not completed a SOC 2 audit or an independent penetration test. Both are planned, neither is done, and it would be dishonest to imply otherwise.
What Richard does not do
- No selling of your data. Ever. There is no advertising business here and no affiliate relationship inside Richard.
- No moving money. Richard reads and recommends — he cannot initiate a trade, a transfer, or any account action, by design.
- No sharing your financial data with other users, and no advisor-facing product.
Deleting your data
You can disconnect an institution at any time from Settings, which revokes the Plaid connection. To delete your account and the household data with it, email [email protected] and it will be done. Backups roll off within 30 days.